At 08:00 Coordinated Universal Time (UTC) on Monday, September 28, 2026, which was 1:30 PM in India, Bitget users began moving Bitcoin off an exchange that had been robbed of $387.5 million four days earlier. Eighty-five hours and 29 minutes separated the moment the exchange detected the attack from the moment its first customers were allowed to leave with their coins.
Nineteen months before that, Bybit had suffered the largest crypto theft on record, close to $1.5 billion, and kept its withdrawal gates open through the night. In India, meanwhile, users of WazirX who lost access to their crypto on July 18, 2024, are still waiting for the final 15% of what they are owed, 802 days after the money left.
It is worth pausing on that sequence, because it inverts the order one might expect. WazirX suffered the smallest loss of the three exchanges, and yet it is the only one whose customers became creditors, the only one whose crisis was settled in a foreign courtroom, and the only one that left part of every claim inside a token that cannot be sold.
The purpose of this piece is not to rank which exchange was hacked most skilfully, since every centralized exchange is a target and the attackers in all three cases have been linked by investigators or company executives to North Korean state-backed groups. The purpose is to examine what each company did once the money was gone, and to ask why the exchange with the smallest hole produced the longest wait.
The Scoreboard: Three Hacks Measured Side by Side
The figures below are drawn from each exchange’s own disclosures and from The Crypto Times’ reporting, and they establish the scale of the gap before any judgement is made.
| WazirX | Bybit | Bitget | |
|---|---|---|---|
| Date of hack | July 18, 2024 | February 21, 2025 | September 24, 2026 |
| Amount lost | About $230 to $235 million | About $1.46 billion | About $387.5 million |
| Assets affected | About 45% of crypto holdings | One ETH cold wallet | Exchange hot wallets |
| Withdrawal status | Crypto frozen for 463 days | Never paused | BTC reopened after 85 hours 29 minutes |
| Who absorbed the loss | Users, through a court-approved scheme | Bybit’s balance sheet | Bitget’s Protection Fund |
| User recovery | About 85%, remainder in non-tradable tokens | Assets backed 1:1 | Company says balances unaffected |
| Leader on camera within hours | No | Yes | Yes |
WazirX lost roughly one-sixth of what Bybit lost and about three-fifths of what Bitget lost, yet it took approximately 130 times longer than Bitget to return crypto to its users. That ratio, more than any single headline, captures the difference between a security failure and a governance failure.
Three Hacks, Three Clocks, and an Uncomfortable Ratio
The raw figures frame the argument more sharply than any adjective could. WazirX lost roughly $230 million to $235 million on July 18, 2024, which amounted to about 45% of its crypto holdings. Bybit lost about $1.46 billion on February 21, 2025, from a single ETH cold wallet, and Bitget lost about $387.5 million on September 24, 2026, from its hot wallets.
Bybit never paused withdrawals. Bitget paused them for a little over three and a half days before opening Bitcoin withdrawals on a published schedule. WazirX kept crypto withdrawals frozen for 463 days, from the day of the hack until the platform restarted on October 24, 2025. Measured in hours, WazirX’s users waited roughly 130 times longer than Bitget’s for access to their crypto, despite a loss roughly three-fifths the size.
In this writer’s view, that ratio is the most telling number in the entire comparison, because it measures not the skill of the attackers but the choices of the companies that were attacked.
WazirX, July 18, 2024: The Smallest Loss and the Longest Wait
The WazirX story is usually told as a single event, a sophisticated attack on a custody interface. Read closely, the public record describes something longer and more troubling: a breach that sat in plain sight for over a week, a first week of communication built around distinctions rather than disclosures, and a series of decisions that moved the cost of the attack steadily toward the users.
A Breach That Sat Visible for Eight Days
WazirX held a large portion of user crypto in an Ethereum multisignature (multisig) wallet, which requires several signers to approve any transfer, and it accessed that wallet through Liminal, a third-party custody provider.
Three WazirX signers using Ledger hardware wallets, together with one Liminal signer, approved what their screens displayed as a routine transaction, while the payload actually upgraded the wallet’s contract and handed control to the attacker. The exchange confirmed in its July 21 update that the loss exceeded $230 million.
What received far less attention was the timing. The Crypto Times’ two-year investigation found that the malicious contract had been deployed on-chain on July 10, 2024, eight full days before it was triggered, and that neither WazirX, Liminal, nor any third-party monitoring service flagged it. The same investigation noted reports that Liminal’s systems had rejected several suspicious transactions before the successful one, without that anomaly being escalated to the signers.
A hardware wallet exists precisely so that signers verify transactions on the device rather than on a web page, and it remains difficult to reconcile that principle with three senior approvals of a contract upgrade disguised as a transfer.
Two Audits That Cleared the Companies That Paid for Them
The question of responsibility was then handed to competing investigators. According to The Crypto Times’ reporting, Mandiant, commissioned by WazirX, found no compromise on WazirX’s machines and located the failure in the externally managed custody environment, while Grant Thornton, commissioned by Liminal, cleared Liminal’s systems and pointed back toward the client side.
Each company paid for an investigation, and each investigation cleared the company that paid for it. No independent authority has since reconciled the two reports, which means that, more than two years later, there is still no single court-supervised technical account of what happened inside the wallet that held the savings of millions of Indian users.
Hour Zero and the “Temporary” Pause
WazirX suspended Indian Rupee (INR) and crypto withdrawals on the day of the hack and described the measure as temporary. The company later set 1:00 PM Indian Standard Time (IST) on July 18, 2024, as its official freeze point when it rolled back every account balance to that moment.
Michael Pearl, Vice President at blockchain security firm Cyvers, later said that he messaged Nischal Shetty about the drain that morning and that the founder did not initially believe him. The temporary pause on crypto withdrawals would ultimately last 15 months.
The First Week of Communication
The way a company speaks in the first week after a hack usually reveals whom it believes it is accountable to. WazirX’s first week was defined by three moments, each of which, in this writer’s reading, placed the company’s position ahead of the users’ losses.
July 23, 2024: A Distinction Offered as Reassurance
On July 23, 2024, Shetty told users on X that the WazirX platform “was NOT breached” and that the attack had hit a multisig wallet hosted outside the exchange’s product infrastructure. The company’s key insights post repeated the framing while confirming that about 45% of crypto assets had been lost.
The distinction may have carried weight in legal terms, but it offered little to customers, since the wallet that was breached was the wallet that held their crypto. Beneath that post, one user asked whether WazirX carried insurance or maintained a user protection fund and remarked that an earlier question on the subject had gone unanswered. It was arguably the most important question anyone asked that week, and the thread records no reply from the founder.
July 27 to 29, 2024: The Socialized Loss Poll
Nine days after the theft, WazirX asked users to vote on how the loss should be distributed, a proposal that would have extended the damage to customers whose assets had never been held in the compromised wallet.
After criticism from users and from leaders of rival Indian exchanges, Shetty posted a video on X on July 29 explaining that the poll was neither final nor legally binding. Of the three exchanges in this comparison, WazirX faced the smallest bill, and it was the only one that invited its customers to help pay it.
August 8, 2024: The Rollback
WazirX then reversed every trade executed after 1:00 PM IST on July 18 and restored all balances to the freeze point. INR withdrawals later reopened in phases, but 34% of INR balances were frozen in connection with law enforcement investigations, and as The Crypto Times reported in September 2026, some of those balances still have no release date.
Bybit, February 21, 2025: A Record Theft Without a Locked Door
Bybit’s hack is useful to this comparison precisely because it was so much larger. If scale were the decisive factor in how long users must wait, Bybit’s customers should have waited the longest of all, and the record shows that they waited the least.
How the Cold Wallet Was Drained
Bybit, a Dubai-based exchange, was carrying out a routine transfer of ETH from a cold wallet to a warm wallet through Safe{Wallet}, a multisig management tool. According to Bybit’s official incident timeline, the attackers exploited the signing interface at 14:13 UTC, masked the transaction, and altered the wallet’s contract logic, removing 401,347 ETH along with staked ETH derivatives for a total loss of about $1.46 billion.
The method bore a close resemblance to the WazirX attack, which makes the difference in what followed all the more instructive.
The First Night
Ben Zhou, Bybit’s co-founder and CEO, addressed users on X at 15:44 UTC, about 91 minutes after the exploit, confirming that one cold wallet had been compromised and that withdrawals continued normally.
At 16:07 UTC, he stated that Bybit remained solvent even if the stolen funds were never recovered and that client assets were backed on a 1:1 basis, and at 17:15 UTC, he went live on a livestream to take questions directly from users.
About 10 hours after the hack, Zhou reported that more than 350,000 withdrawal requests had arrived and that 99.994% had been completed. At 02:51 UTC on February 22, roughly 12 and a half hours after the exploit, he announced that all withdrawals had been processed. Customers rushed for the exit, and the exchange let every one of them through.
The Months That Followed
Bybit replenished the missing ETH through its own reserves and bridge loans from partners, and launched a public bounty initiative that Bitget is now using in its own recovery. In August 2026, Bybit filed suit against North Korea, and the recovered and frozen amounts remain a small fraction of the stolen total. The notable point is that Bybit’s customers were never required to wait for any of that recovery before regaining access to their money.
Bitget, September 24 to 28, 2026: A Pause With a Published End Date
Bitget did not match Bybit’s decision to keep withdrawals open, and its handling deserves continued scrutiny. What distinguishes it from WazirX is that its pause came with dates attached, and that the company absorbed the loss rather than distributing it.
How the Hot Wallets Were Drained
Bitget, a Seychelles-registered exchange, detected unauthorized transfers at 18:31 UTC on September 24, and its security notice identified exchange hot wallets as the target. CEO Gracy Chen later said the attackers spoofed transaction data so that Bitget’s own authorization system approved the outflows, without stealing private keys or forging user withdrawal requests.
The Crypto Times’ minute-by-minute reconstruction shows a detail that has drawn little attention: a single one-minute wave at 19:16 UTC moved about $185 million, including 13,966 ETH, about 91.4 million XRP and 20.6 million TRX. XRP ultimately formed the largest share of the theft, at roughly 103 million tokens worth about $157 million.
The First Days
The exchange first placed the loss at $351.6 million and, on September 25, raised it to $387.5 million after counting Zcash (ZEC) and TRON (TRX) transfers from the original window, while launching a 5% recovery bounty. On September 26, it published a dated withdrawal schedule covering BTC on September 28, ETH on September 29, USDT on September 30, and all remaining assets on October 2, and stated that its Protection Fund would cover the loss.
Not every avenue has cooperated. THORChain, a cross-chain swap protocol, declined Chen’s request to block the attacker’s routes. Chen’s suggestion of North Korean involvement also remains a company assessment rather than a government finding, and this publication has separately examined how the incident compares with FTX.
What the Three Leaders Chose to Say
Crisis communication is rarely judged by its eloquence and almost always by its timing and substance. Set side by side, the public statements of the three leaders tell their own story.
Ben Zhou and Gracy Chen
Zhou posted within 91 minutes of the exploit, reaffirmed solvency 23 minutes later, and appeared on a livestream within three hours. Chen posted on the night of the hack, explained the method, published a higher loss estimate herself, released a four-day calendar and scheduled a live Ask Me Anything (AMA) session at 07:30 UTC on September 28, thirty minutes before the first withdrawals. Both leaders accepted public embarrassment while their crises were still unfolding.
Nischal Shetty
Shetty’s first substantial public message came five days after the hack and centred on the claim that the platform had not been breached, and his next major intervention was a defence of the socialized loss poll.
On March 8, 2025, with user crypto still frozen, he shared a seventh-anniversary message under the hashtag #WazirXRises, describing the company as “hurt but not out,” while replies beneath the post accused him of having stopped answering user questions.
The contrast is not one of tone alone; it is a contrast between leaders who stood in front of their users and a founder who addressed them largely through statements and hashtags.
The Details That Rarely Make the Headlines
Much of the public conversation about WazirX has settled on a handful of figures, namely the $235 million loss, the 85% repayment and the 95.7% creditor approval. The less-quoted details of the restructuring, several of which surfaced in The Crypto Times’ reporting and in court filings, arguably say more about how the process treated users.
The Wallet Filing and the Vote
When WazirX submitted wallet addresses to the Singapore court, the filing ran to roughly 240,000 addresses, the large majority of them hot wallets under WazirX’s own control, as The Crypto Times reported at the time. For a company whose public messaging leaned on the failure of its custody partner, that filing described a far larger operational surface under WazirX’s own responsibility.
The Singapore High Court rejected the first scheme in June 2025, and in that judgment, according to The Crypto Times’ reading, Justice Kristy Tan noted that the platform had misled users in its post-hack communications. Participation in the first vote stood at about 3.3% of total creditors.
The amended scheme later won approval from about 95.7% of voting creditors by number and 94.6% by value, but those figures describe the voters, not the 4.4 million affected users, most of whom never took part in a foreign legal process conducted in English.
Panama, Zensui and a Ruling That Came Too Late
During the same period, The Crypto Times fact-checked corporate filings showing that the company had redomiciled to Panama and rebranded as Zensui, a move users learned of through the press rather than from the exchange.
In October 2025, the Madras High Court ruled in a separate case that crypto held on an exchange remains the property of the individual user and cannot be socialized against unrelated platform losses, a position that arrived only after the Singapore scheme had been sanctioned.
The Arithmetic Inside the Scheme
Claims were valued at July 18, 2024 prices, the day of the hack, which means users received 85% of a portfolio priced before the subsequent market rally. According to The Crypto Times’ analysis, 33% of locked WRX, the exchange’s own token, was included in the rebalancing calculations, and the scheme provided for a $30 million cost reserve that received little scrutiny before the vote.
WRX itself, which reached an all-time high of $5.94 in April 2021, was trading at about $0.0188 in July 2026, and Binance delisted the token on December 25, 2024.
The Only Arrest
The only arrest Indian police have made in connection with the hack itself was of SK Masud Alam, a man from West Bengal accused of selling a KYC-verified account used in the attack. Two years later, the account seller has faced criminal prosecution, while no individual responsible for designing the custody arrangement or its signing procedures has faced personal legal consequences in any jurisdiction.
What Users Actually Received
The restart on October 24, 2025, was presented as a recovery, and in part it was. The terms, however, deserve to be read in full rather than in summary.
Repaid at Hack-Day Prices, Holding a Token They Cannot Sell
Eligible users received about 85% of their approved claims, and the remaining 15% was converted into Recovery Tokens credited on January 9, 2026, which cannot be traded, withdrawn, or transferred. Buybacks depend on WazirX realizing at least $10 million in unencumbered value within a quarterly cycle, and as of September 2026, no buyback has been publicly confirmed.
When WazirX launched a futures product in May 2026, it pledged that the product’s profits would support Recovery Token holders, but no mechanism for verifying that flow has been disclosed. The product was initially marketed with 20x leverage in early access before the figure was reduced to 10x at public launch, a revision the company did not explain.
The Attackers Kept the Rally
Investigators have frozen only about $3 million of the stolen funds, roughly 1.3% of the total, while the remainder was laundered and largely converted into Bitcoin, which has appreciated since. Users were repaid at hack-day prices, whereas the attackers retained the benefit of every price rise that followed.
The Founder’s Paper Trail
No account of the WazirX aftermath is complete without the transactions surrounding its founder, several of which were disclosed to users only because journalists found them. None of them has been publicly explained by the company.
Transfers Made While Users Waited
On August 13, 2024, less than four weeks after the hack, UAE corporate records show that Shetty transferred his entire stake in Shinjuku FZC LLC, a company linked to the WazirX network, to his wife. Zanmai Labs, WazirX’s Indian operator, recorded a payment of ₹342.28 crore in financial year 2021-22 to a private company controlled by Shetty and his wife. Within a day of the Bybit hack in February 2025, WazirX moved about ₹606 crore off that exchange without explanation to the users whose remaining value it had placed there.
Courts That Could Not Reach Him
In January 2025, Shetty missed a scheduled Singapore court date, and in April 2025, a criminal writ petition filed by 54 victims before India’s Supreme Court was dismissed in under five minutes, with the bench citing the absence of crypto regulation. There is no public record of Shetty appearing in person before any Indian court or investigative agency since the hack.
The Defence of Scale, and Where It Falls Short
The most reasonable defence of WazirX is that Bybit and Bitget are far larger companies with resources to absorb losses that WazirX could not. The point has merit, because a loss equal to 45% of crypto holdings is a different order of damage from a loss confined to one cold wallet or a set of hot wallets, and few observers expected WazirX to cover $235 million from its own balance sheet.
Scale, however, explains only why WazirX could not write a cheque. It does not account for a poll that asked unaffected users to share the loss, for a founder’s insistence that the platform had not been breached, for undisclosed transactions in the weeks after the hack, or for a recovery plan that depends on profits the company has never published. The size of a balance sheet determines whether a company can pay, but it has no bearing on whether that company is candid with the people it owes.
Fairness also requires recording what WazirX did achieve. It did not collapse in the manner of FTX; no evidence has emerged of insider theft of the stolen funds, it returned about 85% of approved claims, and it moved custody to BitGo, an institutional custodian. In this writer’s view, those outcomes represent the minimum users were entitled to rather than an achievement deserving of credit.
Where the Three Exchanges Stand Today
The three exchanges now occupy very different positions, and each of those positions reflects the path chosen after the hack.
Bitget and Bybit
Bitget reopened Bitcoin withdrawals on schedule on September 28, with ETH, USDT, and remaining assets due by October 2, and its credibility will rest on whether each of those dates holds. Bybit has been fully operational since February 2025, with user assets restored on a 1:1 basis, and is pursuing North Korea through the courts.
WazirX
WazirX is operational but substantially diminished. In June 2026, Shetty confirmed that the exchange holds roughly 7 to 10% of the Indian market, compared with the 50 to 60% share it claimed at its peak. At its August 31, 2026 AMA, users received no date for the frozen INR balances and no figures on Recovery Token buybacks, and 15% of user claims remain locked.
A Silence That Has Lasted Two Years
The Crypto Times has repeatedly sought comment from WazirX, Zanmai Labs, and Nischal Shetty throughout its coverage of this story, including on the Recovery Token buybacks, the frozen INR balances, and the founder-linked transactions described above. None of those requests have received a response.
The contrast is hard to overlook. Bybit’s CEO answered questions on a livestream three hours after losing $1.46 billion, and Bitget’s CEO scheduled a public session before the first withdrawal of her exchange’s reopening, while the founder of the exchange that lost the least has not answered this publication’s questions in two years.
The Verdict
The attackers in all three cases belonged to the same category of threat, yet the responses they provoked could hardly have been more different. Bybit suffered the largest theft in the industry’s history and still allowed every customer who wished to leave to do so within a day, and Bitget lost $387.5 million and gave its users a published calendar and a Monday morning restart. WazirX lost about $235 million and, over the following two years, turned its customers into creditors, its crisis into a foreign court case, and the final 15% of their money into a token that cannot be sold.
Hacks are an unavoidable risk for any centralized exchange, but the response to a hack is a matter of choice. Judged by the record of these three companies, WazirX is the one whose choices have consistently asked its users to wait, and it is the one that has yet to explain why.
Also Read: ZachXBT Exposes 5 Launderers Moving $387.5M Bitget Hack Funds for North Korea
Disclaimer: This article is an opinion analysis by the author and does not represent an official finding, allegation, or legal claim by The Crypto Times. The comparisons, ratios, and conclusions set out above are the author’s interpretation of publicly available disclosures, court records, company statements, and prior reporting by The Crypto Times.
The Crypto Times is not asserting that any individual or company committed a crime, hid assets, or acted unlawfully beyond what those public records already state. Readers should treat the piece as commentary on disclosed events, not as an investigative verdict or investment advice.
